Truffle Security found approximately 250,000 live API keys embedded in training datasets hosted on Hugging Face, many with direct software supply chain implications.
Snapshot · The a16z Show
Truffle Security found approximately 250,000 live API keys embedded in training datasets hosted on Hugging Face, many with direct software supply chain implications.
Where this was said
At 18:17 · chapter starts 16:01
Feross offers the most concrete near-term fix on the table: npm's planned 2FA requirement would make the worm's self-propagation mechanism impossible, since no automated publish could happen without a human interactively confirming. He believes it's the right call. But the disruption will be enormous — virtually every CI/CD pipeline that auto-publishes packages will break overnight. And the harder problem remains: npm has the backing of GitHub and Microsoft. Most of the critical registries the world depends on are run by volunteers on donated time, without security teams or enterprise SLAs. These registries won't make similar changes because they can't. Feross illustrates the human dimension with a story: a prolific npm maintainer he knew personally was running a six-letter password, not out of negligence but out of a genuine cultural worldview that the internet should be a high-trust place. That is the population defending the world's software infrastructure. [1] — Feross Aboukhadijeh "npm plans to require interactive human 2FA confirmation before any new package publishes starting January 2027. This would effectively end …" 16:01 [2] — Feross Aboukhadijeh "The world's most critical software infrastructure is maintained by volunteers who have no security teams, no SLAs, and often no security tr…" 17:20
npm has announced plans to require interactive 2FA confirmation before any new package publishes, which would effectively kill npm worms but disrupt existing automation pipelines.
npm plans to require interactive human 2FA confirmation before any new package publishes starting January 2027. This would effectively end npm worms, but it will break the entire ecosystem's CI/CD automation overnight. Other volunteer-run registries won't follow, leaving them as the next target.
The world's most critical software infrastructure is maintained by volunteers who have no security teams, no SLAs, and often no security training. Feross Aboukhadijeh recounted a prolific npm maintainer running a 6-letter password with full conviction that it was fine. Companies relying on this code need to own the vetting responsibility — and fund the people doing the work.
Truffle Security found roughly 250,000 live API keys embedded in training datasets on Hugging Face. One of those keys had push access to a foundational Linux library — meaning malware could have been delivered to most machines on the planet. The discovery wasn't theoretical.
One of the leaked Hugging Face keys had direct push access to a foundational Linux library, meaning malware could have been pushed to most machines on the planet.
Feross Aboukhadijeh argued that relatively small sponsorship amounts of $25K–$50K from enterprises could meaningfully fund security staff at under-resourced open-source package registries.
Sam's initial MVP was coded in approximately one week using ChatGPT voice mode and copy-pasting code, with no prior technical experience.
Sam argues Discord is 10x better than email for building relationships with younger users who rarely check their inbox.
Sam's monthly operating costs include Cursor ($200), AI image generation ($100), AI video generation ($200), hosting ($100), email marketing ($80), and AI compute ($300–$500).
Sam recommends copying days of Discord chat history into ChatGPT and prompting it to list recurring pain points as a fast, free market research technique.
Bhanu and his team built approximately 50 free tools to attract search traffic, each linked back to SiteGPT.
With AI coding tools like Cursor, Bhanu can now create a new free marketing tool in less than 5 minutes by referencing existing tools.
Bhanu filters Ahrefs keyword results to show only those with a keyword difficulty below 10, making them realistic ranking targets for any decent website.
Bhanu sets a minimum search volume of 1,000 monthly searches when selecting keywords to target with free tools.
PropGPT averaged 20 downloads per day right after launching on the App Store through influencer marketing.
We use essential and analytics cookies to run Vuci. To understand how the site is used: Privacy Policy.
Install Vuci on your phone
Add it to your home screen for a faster, app-like experience.
Install Vuci on your phone
Tap the Share button, then “Add to Home Screen”.
A new version is available
Reload to get the latest Vuci.